Legal

Privacy Policy

Last updated: September 10, 2026


1. Introduction

DisputePro AI ("Company", "we", "us") is committed to protecting the privacy of our users and their clients. This Privacy Policy explains how we collect, use, store, and protect information when you use the DisputePro AI platform ("Service").

DisputePro AI is operated by ImproveU LLC, 296 N Millard Ave, Fresno, CA 93727, United States — the entity responsible for the data practices described in this policy, including the text messaging program in Text Messaging (SMS).

2. Information We Collect

Account Information:

  • Name, email address, phone number
  • Organization name and business details
  • Login credentials (passwords are hashed using bcrypt)
  • Billing information (processed by Stripe — we do not store card numbers)

Client Data (uploaded by you):

  • Client names, contact information, addresses
  • Social Security numbers (last 4 stored in plain text; full SSN encrypted with AES-256-GCM)
  • Credit reports and credit scores
  • Dispute history and correspondence
  • Documents (IDs, proof of address, agreements)

Payment Processing Data (Authorize.net):

  • Your Authorize.net API credentials are encrypted with AES-256-GCM before storage
  • Client credit card numbers are never stored — they are tokenized via Authorize.net Customer Profiles
  • We store only the last 4 digits, card brand, and expiration for display purposes

3. How We Use Information

  • To provide, maintain, and improve the Service
  • To process your subscription payments
  • To generate AI-powered dispute letters and credit analysis
  • To send transactional emails (invoices, password resets, dispute updates)
  • To send text messages to people who opted in to receive them (see Text Messaging)
  • To provide customer support
  • To comply with legal obligations

4. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption at rest: Sensitive data (SSNs, API credentials) is encrypted using AES-256-GCM
  • Encryption in transit: All data is transmitted over HTTPS/TLS
  • Password security: Passwords are hashed using bcrypt with salt
  • Access control: Role-based access (Owner, Admin, Agent) limits who can view/modify data
  • Multi-tenant isolation: Each organization's data is logically isolated at the database level
  • PCI compliance: Credit card numbers are tokenized through Authorize.net and never stored on our servers

5. Data Sharing

We do not sell your data. We share data only with:

  • Stripe: Our payment processor for SaaS subscription billing
  • Authorize.net: Payment processing for your client transactions (only when you connect your own merchant account)
  • Anthropic: AI processing of credit reports and dispute letter generation (data is not used for model training)
  • Resend: Transactional email delivery
  • Twilio and wireless carriers: Text message delivery, only for people who opted in to texts, and solely to transmit those messages (see Text Messaging)
  • Vercel: Application hosting and file storage
  • Law enforcement: When required by valid legal process

6. Google User Data

DisputePro AI offers an optional feature that lets you connect your Google account so that emails you send to your own clients are delivered from your own address instead of ours. This section describes exactly what we access and how we use it.

What we request

  • Your email address and basic profile (name, profile picture) — to identify the connected mailbox and display it in your settings
  • Permission to send email on your behalf (gmail.send) — to deliver messages you choose to send to your clients

What we do not do

  • We never read, list, search, modify, or delete any message in your mailbox. The send-only permission we request does not technically permit it.
  • We never send email except as the direct result of an action you take in the app, or an automation you configured yourself.
  • We never send unsolicited or bulk marketing email from your account.
  • We do not use Google user data for advertising, and we do not sell or transfer it.
  • We do not use Google user data to develop, improve, or train generalized AI or machine learning models.
  • No humans read your Google user data, except where required for security, to comply with law, or where you have given explicit consent for support.

Access tokens are encrypted at rest using AES-256-GCM and are used solely to deliver the messages you send. You can disconnect at any time from Settings → Integrations, which revokes our access and deletes our copy of your tokens. You may also revoke access directly at myaccount.google.com/permissions.

DisputePro AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Text Messaging (SMS)

This section applies when you opt in to receive text messages from DisputePro AI, operated by ImproveU LLC (296 N Millard Ave, Fresno, CA 93727), or from a credit repair business that uses DisputePro AI to text its own clients (the "Business").

What we collect

  • Your mobile phone number
  • Your SMS consent record: the date and time you opted in, the exact consent wording you were shown, and where you gave consent (a web form, client portal activation, or a consent recorded by the Business's staff)
  • Message content and delivery data: the text messages sent to and received from you, timestamps, delivery status, and any STOP or HELP replies

How consent is collected

Consent to receive text messages is collected through an opt-in checkbox that is unchecked by default, on a web form or when you activate your client portal. Checking the box is optional. Consent to receive text messages is not a condition of any purchase or service — you can submit the form or activate your portal without it.

How we use it

  • To send the messages you agreed to receive: account notifications, appointment reminders, service updates, and replies to your messages
  • To process STOP (opt-out) and HELP requests
  • To keep a record of your consent as required by law

Sharing

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

The only recipients of your mobile information are the service providers that deliver the messages — our messaging provider and wireless carriers — and they receive it solely to send the messages you asked to receive.

Opting out

Reply STOP to any message to stop receiving texts, or reply HELP for help. You can also contact us at privacy@disputepro.net. See the Text Messaging Terms for the full program terms.

8. Data Retention

We retain your data for as long as your account is active. Upon account deletion, we will delete your data within 30 days, except where retention is required by law. Backups are purged within 90 days. You may request data export at any time by contacting support.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data ("right to be forgotten")
  • Export your data in a portable format
  • Opt out of marketing communications
  • Restrict or object to data processing

To exercise these rights, contact us at privacy@disputepro.net.

10. Cookies & Analytics

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising pixels. We may collect anonymous usage analytics to improve the Service.

11. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect information from children.

12. California Privacy Rights (CCPA)

California residents have additional rights under the CCPA, including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.

14. Contact Us

For privacy questions or data requests:

Email: privacy@disputepro.net